Alerting

Filter data sended using saved search with action webhook or email action

TISKAR
Builder

Hello Splunker's

I programmed a saved search with a send webhook data action to send the result in json format. I noticed that the data sent contains additional information like app name eand result_link:

INFO -: {"app" => "search", "results_link" => "http: // splk-sh: 8000 / app / search / search? ....

In fact, I don't want to display this information on my results; i searched in advanced actions i found:

action.webhook.command: sendalert $action_name$ results_file="$results.file$" results_link="$results.url$"

i tried to delete result_link but it doesn't work. 

did you encounter this problem on whebook or even email action can be the same.

Thank you

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...